What does SLSA Build L1 add over L0 when the provenance is written by the machine that built the artifact?
answer
- L0 is the absence, not a control
- Ask who wrote the document
- Defined build process plus distributed provenance
- Same machine describes itself
- Catches mistakes, not forgery
basics
~20 sBuild L0 means no provenance at all. L1 means provenance exists and is distributed: a machine-readable record of how the artifact was built. Self-issued and unsigned, it catches mistakes and supports investigation, not a determined forger.
solid answer
~50 sL0 is the absence of a level: the consumer gets an artifact and nothing describing where it came from. Build L1 asks for two things — the build runs from a defined, repeatable process rather than ad-hoc manual steps, and provenance is generated and distributed to consumers. That provenance names the artifact by digest and records the source revision, the build entry point and the parameters used. Because v1.0 lets the producer generate it themselves, unsigned, on the same machine that did the build, it is evidence against error, not against an adversary: whoever controls that machine controls the document too. It still pays for itself — you can spot a release cut from the wrong branch, answer "which commit is in the build our customers have" in minutes, and you have forced the build to be written down at all.
go deeper
Be ready to say what provenance is in one sentence, that L0 means none exists, and that L1 means it exists and reaches consumers even if nobody signed it.
Explain the two halves of L1 — a defined, repeatable build process and generated, distributed provenance — and why self-issued provenance defends against error rather than against an attacker.
Show what you would actually do with L1 output: compare recorded source ref against the release record, keep provenance retrievable by digest rather than in expiring logs, and know which rung fixes the self-attestation problem.
Own the argument for spending anything here at all: L1 is cheap, buys incident answers and mistake detection immediately, and its real payoff is that it forces every build to be a defined process before you attempt anything stronger.
## What the build track is grading SLSA's build track does not grade whether software is good, whether its dependencies are patched, or whether its code was reviewed. It grades one narrow thing: **how much a consumer can believe a statement about how an artifact was produced**. The rungs, L0 through L3, are ordered by the strength of that evidence. Understanding the bottom two rungs is mostly about understanding what a document says versus what it proves. ## Build L0 L0 is not a control; it is the name for the absence of one. Nothing is claimed and nothing is produced. A consumer holding the artifact has the bytes and nothing else — no record of which source revision it came from, which build entry point ran, which parameters were supplied, or what machine did the work. Every question about origin is answered by asking a person, and the answer is not checkable. ## Build L1 Build L1 asks the producer to do two connected things: 1. **Follow a consistent, defined build process.** The build has to be expressed as something repeatable rather than a sequence of commands somebody remembers. This is the requirement people skip over, and it is the one that does the quiet work — you cannot describe a build you cannot name. 2. **Generate provenance and distribute it to consumers.** Provenance is a machine-readable document that identifies the artifact by cryptographic digest and describes how it came to be: the source it consumed, the build entry point, the external parameters, and who or what ran it. What v1.0 explicitly does **not** require at L1 is that the document be signed, or that anything other than the producer's own build produce it. Provenance emitted by a script on a maintainer's workstation, alongside the artifact that workstation just built, satisfies L1. ## The laptop case Take a mobile release bundle built on a maintainer's laptop and uploaded to a store console. Add L1: the release script now emits a provenance document, and it ships next to the bundle in the internal release record. What you gained is real: - **Mistake detection.** The bundle was cut from a personal branch, or built with the staging API endpoint baked in, or from a tag that was moved after review. All of that is visible in the parameters, and visible to a reviewer who was not in the room. - **Incident answers.** When a handset-side bug shows up in a shipped build, "which source revision is in the artifact with this digest" is a lookup rather than an archaeology project. - **A consumer baseline.** Someone downstream can at least compare the digest they received to the digest the provenance describes, and check the source repository is the one they expect. What you did not gain is anything against a person. The attestor and the subject are the same principal: the machine that built the artifact is the machine that wrote the description of the build. Compromise that workstation — malware in a developer tool, a stolen session, a device someone else is holding — and the same access that changes what gets built changes what the document says it built. Signing it with a key that also lives on the laptop does not change that; it authenticates the same principal to itself. So L1 provenance is an **integrity aid against accident and a forensic record**, not a defence against forgery. That is precisely why the ladder does not stop there: the next rung moves the job of producing and signing the document off the thing being described and onto the build platform. ## How to use L1 well Two habits make L1 worth more than it looks: - **Distribute it where the consumer actually is.** Provenance in a build log that expires in thirty days is not distributed. It belongs next to the artifact, retrievable by digest. - **Have something read it.** A level is only worth what a consumer checks. Even at L1, a release reviewer comparing the recorded source ref against the release ticket catches the class of error the rung exists for. ## The common confusions "We publish provenance, so we're covered" mistakes a description for a guarantee. "It's signed, so it's L2" mistakes the existence of a signature for the identity of the signer. And "provenance tells you what's inside" mixes up the artifacts entirely: an SBOM says what is inside, provenance says how it came to be. At L1 you have a claim about how it came to be, made by exactly the party you would most want an independent statement about.
- If L1 provenance can be forged by whoever holds the machine, why bother producing it at all?Because most bad releases are accidents, not attacks: wrong branch, wrong parameters, a tag moved after review, a build from a dirty working tree. L1 makes those visible to someone who was not present. It also gives incident response a digest-to-revision lookup, and it forces the build to be written down as a repeatable process — which is the prerequisite for every rung above it.
- Does signing that provenance on the same laptop move the build up the track?No. A signature says who vouched for the statement, and here the voucher is the same principal that produced the artifact and could have written anything into the document. The build track's next rung is defined by the hosted build platform generating and signing the provenance itself, not by a signature appearing anywhere at all.
- What does provenance at any level not tell you about the artifact?It does not tell you what is inside — that is an SBOM's job — and it makes no claim that the code is safe, that dependencies are patched, or that anyone reviewed the source. Provenance answers how the artifact came to be, and the build track grades how much you should believe that answer.
A shipping label the sender printed and stuck on their own parcel. It genuinely helps when the sender fat-fingers the address, and it is worth nothing the moment the sender is the problem.
saying these in an interview costs you the question
- Says L0 is a level with some minimum requirements
- Thinks any signature on provenance means at least L2
- Claims L1 provenance proves the artifact was not tampered with
- Describes provenance as a list of the artifact's components
- Treats provenance stored only in expiring build logs as distributed